AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-2428

MEDIUM · CVSS 4.7 EPSS 0.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-04-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.7. It affects WordPress.

CVE
CVE-2024-2428
Severity
MEDIUM
CVSS
4.7
EPSS
0.50%
WordPress

Original NVD Description

The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks